MIT called it the shadow AI economy: employees using consumer tools on company data without approval, because the work is easier that way and nobody told them not to. Governance is not a compliance exercise — it is the difference between AI being an asset and being a disclosure event.
Most governance conversations start with a hypothetical: what if we deploy AI and something goes wrong. That framing is already out of date. Your team adopted AI months ago, individually, using whatever was free and convenient.
The exposure is not theoretical. Client information pasted into a consumer chatbot to summarise a call. A contract uploaded to a free tool to check a clause. Candidate CVs run through a model to rank them. Each is a person doing their job faster, and each is data leaving your control under terms nobody has read.
Banning it does not work — it moves the behaviour further out of sight. What works is naming approved tools, drawing clear lines about data, and making the compliant path the easy one.
Short, specific, and written so an employee can follow them without asking a lawyer.
A named list, with the reason each is on it and what it may be used for. An approved option that is genuinely good is the most effective control you have — people route around rules that make their work harder.
Plain-language classification: what is fine, what needs a named approval, and what never leaves your systems. Most breaches we see are not defiance — they are people who had no idea where the line was.
Hiring, credit, pricing, medical, legal and disciplinary decisions need a named human owner regardless of how confident a model is. Written down before an automation is built, not after something goes wrong.
Where data is processed and stored, whether it trains their models, what the retention and deletion terms are, and what happens if they are acquired. A short checklist applied before purchase, not after renewal.
Enough record of automated decisions to reconstruct what happened and why. If you cannot answer “why did the system do that?” six months later, you cannot defend it to a client or a regulator.
A clear position on how AI is used in your service, ready before a client asks in a procurement questionnaire. Increasingly this shows up in contracts, and having an answer already is becoming a competitive advantage.
What leadership teams ask once they realise this is already happening.
It is if you write it like a legal document and email it once. The version that works is two pages, names specific approved tools, gives concrete examples of allowed and prohibited use, and is introduced by explaining the reasoning rather than issuing rules.
The single biggest factor in compliance is whether the approved path is good. If the sanctioned tool is worse than what people are already using, the policy loses and you have simply made the behaviour invisible.
Your clients increasingly are, and their obligations flow to you through contracts. AI questions are appearing in standard procurement questionnaires, and a vague answer is now a reason to lose a deal.
There is also plain commercial exposure that has nothing to do with regulation — a confidentiality breach, a client discovering their data went into a third-party tool, or an automated decision you cannot explain.
If you operate in or sell into the EU, obligations depend on how your systems are classified, and the higher-risk categories carry real requirements. We will flag where you plausibly fall and what that implies.
We are not lawyers and we will not pretend to be. What we do is get you organised — an inventory of systems, documented decisions, and logging — so that when you take legal advice you are not starting from nothing. That preparation is most of the cost either way.
It can, and over-governing is a real failure mode — a heavyweight review board for a tool that drafts internal meeting notes will simply be bypassed.
The framework should be proportionate: light-touch for low-risk internal use, genuinely strict where decisions affect people's money, employment, health or legal position. Applying the same weight to both is how you get a policy nobody follows.
In most mid-sized companies it lands on operations, legal, or whoever raised the question — which is to say, nobody with the time. That is a large part of why the fractional role exists.
The goal is to hand it over. A framework somebody internal can run, with a named owner and a review cadence, beats a consultant permanently holding the only copy.
The readiness audit includes a shadow-AI review: what your team is actually using, on what data, under whose terms.